ossim - AlienVault
ossim - AlienVault
ossim - AlienVault
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
4.2 Data Flow<br />
To give a better understanding of how each product is integrated, we offer the following step-bystep<br />
description of data flow beginning with the generation of an event:<br />
1. Events are processed by the detectors until an alert is produced in response to<br />
identification of a pattern or anomaly.<br />
2. If necessary, alerts are processed by the consolidators before being sent. The<br />
consolidators send alerts in groups to occupy a minimum of bandwidth.<br />
3. The collector receives alerts using various open communication protocols.<br />
4. The parser normalizes and saves them in the event database.<br />
5. The parser also prioritizes alerts according to the security policy defined in the<br />
framework and information in the systems inventory about the system under attack.<br />
6. The parser assesses the immediate risk represented by the alert and sends an alarm<br />
to the control panel as necessary.<br />
7. Prioritized alerts are sent to each correlation process, which updates their state<br />
variables and eventually sends new alerts with more complete or reliable<br />
information. These alerts are re-sent to the parser to be stored, prioritized, assessed<br />
for risk, etc.<br />
8. The risk monitor periodically displays the state of each risk index as calculated by<br />
CALM.<br />
9. The control panel shows the most recent alarms, updates the state of all the indices<br />
which it compares to their thresholds, and sends out new alarms or performs the<br />
appropriate actions as necessary.<br />
10. From the control panel, the administrator can link and view all events occurring at the<br />
time of the alert using the forensic console.<br />
11. The administrator can also check the concurrent state of the machine involved using<br />
the use, profile, and session monitors.<br />
27